Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

reuters+1cyber-defencealgemeiner+1Britain, the United States and the Netherlands on Tuesday issued a joint cybersecurity advisory exposing spyware they say is wielded by Iranian state-linked actors to surveil dissidents, activists and journalists around the world. The coordinated warning marks the latest effort by Western intelligence agencies to counter what they describe as Tehran's use of digital tools to repress critics of the regime abroad.
The UK's National Cyber Security Centre, part of GCHQ, identified the spyware family as "CHOSEN BRICK" — the same malware the FBI tracks under the name "HEAVYGRAM". Both agencies attribute it to Iran's Ministry of Intelligence and Security (MOIS). The advisory was co-authored by the FBI and the Netherlands' AIVD intelligence service.reuters+5
According to the advisory, CHOSEN BRICK runs on Windows devices and can steal emails, extract messaging histories from WhatsApp Meta Platforms, Inc. and Telegram, capture screen content, copy saved browser passwords, and covertly activate a device's microphone. The malware is persistent, surviving device reboots. The FBI said its investigation traces related activity back to at least 2023.algemeiner+2
The NCSC said attackers typically posed as trusted contacts on messaging apps, building personal rapport over extended conversations before tricking targets into downloading malicious files. In some cases, operatives used fabricated documents — including fake MRI test results — to persuade victims to install the software.arabnews+3
"The details of this cyber campaign reveal how Iran ruthlessly uses digital surveillance in pursuit of its aim to repress critics of the regime, stealing emails and messages and accessing devices," said Paul Chichester, NCSC director of operations.algemeiner+1
The NCSC said some victims' personal details later appeared on pro-Iranian leak sites, where stolen data was published by a hacking persona known as "Handala Hack". The FBI's advisory described Tuesday's release as an update to a March 2026 warning about the same MOIS-linked campaign.arabnews+2
The three agencies urged at-risk individuals to avoid opening files sent through messages or links, to download software only from official sources, and to keep operating systems and antivirus tools up to date. Network administrators were advised to enforce phishing-resistant multi-factor authentication and monitor logs for indicators of compromise published alongside the advisory.cyber-defence+1
The trio of agencies assessed that Iran "almost certainly" uses cyber operations to suppress people it sees as threats.reuters+1